TISAX anchors

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

Primary documents, operating bodies, audit providers, related standards, named voices, reference resources for the TISAX cluster.

Primary documents

  • VDA-ISA workbook โ€” the catalogue. Excel-format spreadsheet with controls, maturity-level criteria, scoring guidance. Current major version: 6.0 (late 2023), with maintenance updates through 2024-2025. Distributed by VDA via vda.de and via ENX participant portal.
  • TISAX Participant Handbook โ€” ENX-published operational document describing the assessment process, label types, registration steps, audit-provider engagement. Updated periodically; current ~2024-2025.
  • TISAX Assessment Provider Handbook โ€” operational guidance for audit providers. Less commonly read by suppliers but useful for understanding auditor expectations.
  • VDA-ISA criteria mapping โ€” VDA-published spreadsheet mapping VDA-ISA controls to ISO/IEC 27001:2022 Annex A and other reference frameworks. Useful for dual-implementation orgs.

Operating bodies

  • ENX Association โ€” neutral operator. Frankfurt-based. enx.com. Maintains the registry, accredits audit providers, runs the portal. Annual participant fees fund operations.
  • VDA (Verband der Automobilindustrie) โ€” content owner. Authors and revises VDA-ISA. vda.de.

Accredited audit providers

ENX-accredited audit providers as of 2026 (illustrative, not exhaustive; check enx.com for current list):

  • TรœV SรœD (Munich)
  • TรœV Rheinland (Cologne)
  • TรœV Nord (Hannover)
  • TรœV Hessen
  • DEKRA (Stuttgart)
  • DQS (Frankfurt)
  • KPMG
  • Deloitte
  • PwC
  • EY
  • BSI Group (UK origin, German operations)
  • GRC partner firms (specialist auditors with TISAX accreditation in addition to ISO 27001)

Auditor accreditation is checkable via the ENX portal participant view.

  • ISO/IEC 27001:2022 โ€” the international ISMS standard. Most controls overlap; implementations typically converge.
  • ISO/IEC 27002:2022 โ€” controls implementation guidance.
  • ISO/IEC 27005:2022 โ€” risk management. Useful for risk-assessment methodology underlying VDA-ISA control selection.
  • ISO/IEC 27701:2019 โ€” privacy information management. Complements VDA-ISA Data Protection module.
  • ISO/IEC 27017:2015 โ€” cloud-specific controls. Useful when supplier uses cloud-hosted services for automotive customer data.
  • ISO/IEC 42001:2023 โ€” AI management system. No formal TISAX integration yet, but practitioners are using it as an AI-specific overlay.
  • GDPR (EU 2016/679) โ€” privacy regulation. Data Protection module aligns explicitly.

Adjacent automotive-sector standards

  • ISO/SAE 21434:2021 โ€” Road vehicles โ€” Cybersecurity engineering. Product-side cyber-security for vehicles. Different scope from TISAX (which is about supplier-org information security), but relevant for development partners working on connected / autonomous vehicle systems.
  • UN R155 / UN R156 โ€” UN ECE regulations on vehicle cybersecurity (R155) and software update management (R156). Mandatory for vehicle type approval in UN member states from 2022.
  • ASPICE (Automotive SPICE) โ€” software process maturity model for automotive. Same SPICE roots as TISAX maturity levels. Common in development-partner relationships alongside TISAX.
  • VDA 6.x โ€” automotive quality management family (parallel to ISO 9001). Often required alongside TISAX in OEM contracts.

Named practitioners and reference voices

TISAX is a smaller practitioner community than ISO 27001. Named voices include:

  • ENX Association staff โ€” public-facing communications, conference presentations, webinars. The most authoritative source on operational mechanics.
  • VDA Information Security Working Group โ€” authors the catalogue. Less individually-attributed than ENX side.
  • TรœV / DEKRA / KPMG senior auditors โ€” industry-conference presentations, particularly at VDA events and Hannover Messe. Surface common findings and emerging audit focus areas.
  • Mid-market German GRC consultancies (KPMG GRC, Deloitte Risk Advisory, PwC, EY, plus specialist Mittelstand-focused firms) โ€” practitioner content via industry publications.

For independent or critical voices, the field is thinner than for ISO 27001. Most TISAX writing is implementation-focused; critical analysis is rare in published form.

Reference resources

  • enx.com โ€” official TISAX operating site. Participant portal, audit-provider list, handbook downloads.
  • vda.de โ€” VDA-ISA distribution. German-language primary.
  • VDA Information Security Conference โ€” annual industry event covering TISAX and adjacent automotive InfoSec.
  • Hannover Messe โ€” broader industrial event with VDA / ENX presence.
  • TISAX participant member webinars โ€” periodic ENX-hosted Q&A sessions, open to participants.

Regulatory and procurement context

  • OEM contract clauses โ€” VW Group, BMW Group, Mercedes-Benz, Audi, Porsche, Bosch, Continental, ZF, Schaeffler, Hella, Mahle have TISAX flow-down clauses in supplier contracts. Wording varies but mechanism is consistent.
  • GDPR enforcement on automotive PII โ€” telematics, customer-relationship, employee, dealer-network data. Data Protection label increasingly required by OEMs handling EU resident data.
  • EU NIS2 Directive โ€” automotive critical-infrastructure operators in scope under member-state transposition. Overlap with TISAX coverage; non-equivalent.
  • EU AI Act โ€” high-risk classification for some automotive AI use cases (driver monitoring, ADAS) brings additional obligations. ISO 42001 + TISAX combined positioning emerging.

See also